Compensation
This employer didn't list pay. Model a likely range with the calculator.
Model this offer in the calculatorJob description
Full-Time Springfield/Boston
The Opportunity
As a Third-Party Risk Consultant you will play a crucial role in implementing the third-party risk framework. This position is responsible for executing third-party risk assessments and due diligence activities across the MassMutual's third-party ecosystem. Additionally you will support the adoption of risk management practices across the ETX organization. As a key member of the ETX Third-Party Technology Assurance team you will help drive change and enhance operational efficiency throughout the organization.
The Team
The ETX Governance Risk & Compliance Team is comprised of governance and risk professionals responsible for implementing governance processes and risk management practices for the ETX (Information Technology) organization. We work closely with our business and technology partners and succeed together by designing practical and effective technology governance and risk management solutions to increase operational efficiency.
The Impact
- Analyze third-party services data flows and system integrations to identify and recommend inherent and residual risk exposure.
- Collaborate with issue management teams to ensure identified risks including vulnerabilities are appropriately tracked communicated and remediated
- Contribute to status reporting and metrics tracking for ongoing third-party risk activities
- Evaluate document communicate and support breach event and incident response activities
- Execute risk evaluation procedures by reviewing evidence documenting observations and recording results in accordance with defined templates and quality standards
- Identify control gaps weaknesses or non-compliance issues and clearly document and recommend findings for further review and disposition
- Partner with senior practitioners to support risk rating determinations and escalation decisions
- Apply knowledge and discretion when performing risk assessments to ensure third parties meet security and technology standards in alignment with established practices and procedures
- Proactively escalate delays gaps in information or emerging risks to the team lead
- Research and consult with internal subject matter experts to understand and document risk identified through risk assessments and due diligence practices and communicate the findings to stakeholders
The Minimum Qualifications
- 2+ years of experience in risk management and/or completing third-party risk assessments
- 2+ years of experience implementing metrics to track status identify trends and surface potential issues
- 2+ years of experience working in an enterprise GRC platform including proficient use of Excel import/export functions
The Ideal Qualifications
- Bachelor's degree preferably in technology cybersecurity risk management or business-related field
- 3+ years of experience in third-party risk management technology risk cybersecurity audit or testing controls
- Proficiency with SharePoint and related tools used to execute an effective regulatory compliance program
- Experience communicating regulatory requirements to technical and non-technical audiences and facilitating discussions between ETX owners Compliance and Law to ensure a shared understanding and effective compliance
- Foundational understanding of third-party risk domains including:
- Cybersecurity and data protection
- Cloud/SaaS risk considerations
- Identity and access management (e.g. SSO vs. standalone access)
- Business continuity and resiliency
- Familiarity with industry frameworks such as NIST ISO 27001 SOC 2 or similar
- Ability to interpret control evidence and assess adequacy relative to risk
- Strong written and verbal communication skills with the ability to interact effectively with internal stakeholders and third parties
- Demonstrated ability to execute with limited guidance while meeting deadlines in a structured process-driven environment
- Strong attention to detail and documentation discipline
What You Can Expect at MassMutual
MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role you can expect:
- Clear areas of ownership and accountability with work that connects directly to company and customer outcomes
- A collaborative environment where perspectives are welcomed
- Access to learning development and internal networks that support continuous growth and skill-building over time
- Employee-led communities and forums that foster connection learning and inclusion across the organization
- A culture grounded in integrity responsibility and stewardship-supported by a company with a strong legacy and a future-focused mindset
#LI-RK1
MassMutual is an equal employment opportunity employer. We welcome all persons to apply.
If you need an accommodation to complete the application process please contact us and share the specifics of the assistance you need.
California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA) please visit our California Consumer Privacy Act Disclosures page.
Salary Range: $86200-$113100
Skills Required
- 2+ years of experience in risk management and/or completing third-party risk assessments
- 2+ years of experience implementing metrics to track status identify trends and surface potential issues
- 2+ years of experience working in an enterprise GRC platform including proficient use of Excel import/export functions
- Bachelor's degree preferably in technology cybersecurity risk management or business-related field
- 3+ years of experience in third-party risk management technology risk cybersecurity audit or testing controls
- Proficiency with SharePoint and related tools used to execute an effective regulatory compliance program
- Experience communicating regulatory requirements to technical and non-technical audiences and facilitating cross-functional discussions
- Foundational understanding of third-party risk domains (cybersecurity data protection Cloud/SaaS identity and access management business continuity)
- Familiarity with industry frameworks such as NIST ISO 27001 SOC 2 or similar
- Ability to interpret control evidence and assess adequacy relative to risk
- Strong written and verbal communication skills and ability to interact with internal stakeholders and third parties
- Demonstrated ability to execute with limited guidance while meeting deadlines in a structured process-driven environment
- Strong attention to detail and documentation discipline
What the Team is Saying
_0.jpeg)



What We Do
Since 1851 MassMutual’s commitment has always been to help people protect their families support their communities and help one another. This is why we want to inspire people to Live Mutual. We’re people helping people. Together we’re stronger.
Why Work With Us
MassMutual has the financial security and stability of a 170+ year old company with the culture and energy of a startup. We work every day with the customer front of mind to build the best digital experience in the industry.
Gallery
MassMutual Teams
MassMutual Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
We believe in capitalizing on the best of being together in our offices as well as personal flexibility. Our workplace philosophy puts office collaboration first combined with flexibility to work remotely.
Similar Jobs
MassMutual
Investment Accounting Data Analytics and Reporting Manager
MassMutual
Business Systems Analyst
MassMutual
Director of Alternative Investments
Related roles



